Splunk Developer (SIEM Team)

Worky

Wheaton (IL)

On-site

USD 87,000 - 141,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Abra Professional Services in Israel is seeking a Splunk Developer to join a SIEM team within a leading financial organization. You will develop and maintain Splunk-based security solutions, integrate log sources, and build dashboards and detection content.

The role requires strong SPL, Python, and React skills, plus deep knowledge of SIEM and security monitoring. It is a full-time, on-site position based in Central Israel, offering opportunities to enhance monitoring capabilities across the

Qualifications

  • 3+ years hands-on Splunk Enterprise and/or Splunk Cloud experience.
  • Advanced SPL query development (joins, stats, tstats, transactions, lookups).
  • Dashboard, alert, report, and saved search development.
  • Data ingestion with Syslog, HEC, and REST APIs.
  • Knowledge of indexes, sourcetypes, props.conf, transforms.conf.

Responsibilities

  • Develop and maintain Splunk solutions.
  • Build dashboards, reports, alerts, saved searches.
  • Create and maintain detection rules and monitoring content.
  • Onboard new data sources via Syslog, HEC, REST APIs.
  • Develop backend components with Python.
  • Develop UIs with React.
  • Tune performance and optimize searches.
  • Collaborate with cyber security, infra and ops teams.

Skills

Splunk
SPL
Python
React
JavaScript
HTML/CSS
JSON parsing

Tools

Syslog
HEC
REST APIs
Git
CI/CD
Docker
Kubernetes

Job description

Abra Professional Services is seeking a Splunk Developer.

We are looking for a skilled Splunk Developer to join a SIEM team within a leading financial organization. The role involves developing and maintaining Splunk-based security solutions, integrating log sources, creating dashboards and detection content, and enhancing monitoring capabilities across the organization's cyber security environment.

This role requires strong expertise in Splunk Enterprise/Cloud, advanced SPL development, Python programming, and React development, alongside a deep understanding of SIEM and security monitoring technologies.

A full-time, on-site position, based in Central Israel.

Key Responsibilities:

  • Develop and maintain solutions on the Splunk platform.
  • Design and build advanced dashboards, reports, alerts, and saved searches.
  • Create, optimize, and maintain detection rules and monitoring content.
  • Integrate and onboard new data sources using Syslog, HEC, REST APIs, and other ingestion methods.
  • Develop backend components and automations using Python.
  • Build and maintain internal operational tools and user interfaces using React.
  • Perform performance tuning and search optimization across the Splunk environment.
  • Collaborate with cyber security, infrastructure, and operations teams to improve monitoring and detection capabilities.
Requirements
  • 3+ years of hands-on experience with Splunk Enterprise and/or Splunk Cloud.
  • Strong experience writing advanced SPL queries, including joins, stats, tstats, transactions, and lookups.
  • Experience developing and maintaining dashboards, alerts, reports, and saved searches.
  • Experience implementing and managing data inputs via Syslog, HEC, and REST APIs.
  • Strong understanding of indexes, sourcetypes, props.conf, and transforms.conf.
  • Experience with Splunk performance tuning and search optimization.
  • 2+ years of Python development experience.
  • Experience working with REST APIs, JSON/XML parsing, and data normalization.
  • Experience developing applications with React, including Hooks, Components, and State Management.
  • Strong knowledge of JavaScript ES6+, HTML, and CSS.
Advantages
  • Experience with Splunk SOAR.
  • Experience in Cyber Security, SIEM, or SOC environments.
  • Experience integrating with cloud platforms (AWS, Azure, GCP).
  • Experience integrating security tools such as EDR, IAM, and CI/CD solutions.
  • Experience working with Git and CI/CD pipelines.
  • Familiarity with Docker and Kubernetes.
  • Splunk certifications (Power User, Admin, Architect).
  • Academic degree in Computer Science, Information Systems, Cyber Security, or a related field
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Splunk Developer — SIEM, Dashboards & Automation
Splunk Developer — SIEM, Dashboards & Automation

Worky • Wheaton (IL)

On-site
USD 87,000 - 141,000
Splunk engineer
Splunk engineer

E*Pro Inc • New York (NY)

On-site
USD 100,000 - 130,000
Splunk Engineer
Splunk Engineer

RapidSoft Corp • Reston (VA)

On-site
USD 90,000 - 120,000
Splunk Administrator/Engineer
Splunk Administrator/Engineer

Resolution Technologies, Inc. • Georgia

On-site
USD 80,000 - 110,000
IT Security SIEM Engineer – Splunk Experience Required
IT Security SIEM Engineer – Splunk Experience Required

Jobtailor • New York (NY)

On-site
USD 120,000 - 160,000
Splunk Engineer at Fusion HCR Oakton, VA
Splunk Engineer at Fusion HCR Oakton, VA

Hong Kong Study Skills Research Institute • Oakton (VA)

On-site
USD 90,000 - 130,000
Splunk Subject Matter Expert (SME) & Enterprise Monitoring Engineer
Splunk Subject Matter Expert (SME) & Enterprise Monitoring Engineer

Empower Professionals Inc - Talent & IT Services • Frisco (TX)

Hybrid
USD 120,000 - 150,000
Senior Splunk Administrator
Senior Splunk Administrator

Compunnel, Inc. • Houston (TX)

On-site
USD 100,000 - 130,000
Cybersecurity Engineer 3
Cybersecurity Engineer 3

Mbi Llc • Richmond (VA)

On-site
USD 110,000 - 160,000
Data Engineer With Splunk
Data Engineer With Splunk

Veriipro • Quincy (MA)

On-site
USD 100,000 - 130,000